Untrusted Device Access via Trusted Intermediary Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current content management systems lack fine-grained access control for untrusted devices and unauthorized user accounts, making it difficult to securely access sensitive data on unfamiliar or insecure computing devices, and are cumbersome for non-traditional devices like smart TVs with limited interfaces.
Innovation Solution
Implementing a system that allows users to authenticate untrusted devices or unauthorized user accounts through a trusted device, using authentication keys sent as text strings, QR codes, or sounds, enabling precise control over data access, including time limits and sharing instructions, and allowing access on a per-user-account basis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control is implemented on a per-device basis, then security and privacy are improved, but device complexity and operational difficulty increase
Solution Approach 1:
The patent introduces an authentication key as an intermediary element that mediates between the user and the untrusted device. Instead of implementing complex per-device access control mechanisms directly on the device, the system uses a simple authentication key (displayed as visual code or sound) that the user presents to the device. This intermediary simplifies the interaction while maintaining security, as the device only needs to verify the authentication key rather than implement full access control management.
Solution Approach 2:
The patent creates a copy of the authentication mechanism by generating an authentication key that can be displayed in multiple formats (visual code on screen, sound output). This copying approach allows the authentication information to be transferred to the untrusted device through various channels, simplifying the access control process while maintaining security. The device receives and processes this copied authentication information without needing complex access control infrastructure.
2Reliability
If fine-grained access control is implemented, then data privacy is improved, but ease of operation deteriorates
Solution Approach 1:
The authentication key serves as an intermediary that simplifies the authorization process. Instead of requiring users to navigate complex access control settings or enter multiple credentials on untrusted devices, the system provides a simple authentication key that can be presented visually or through sound. This intermediary element bridges the gap between fine-grained access control requirements and user convenience, allowing rapid authorization while maintaining data privacy.
Solution Approach 2:
The patent replaces traditional mechanical authentication methods (keyboards, mice, complex UI interactions) with alternative sensing methods. The untrusted device uses its camera to capture visual authentication codes or its microphone to capture sound-based authentication keys. This substitution eliminates the need for complex manual input on devices with limited interfaces, greatly improving ease of operation while maintaining secure authentication.
3Reliability
If authentication requires complex input on untrusted devices, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent replaces mechanical input methods (keyboard typing, mouse clicking) with sensor-based authentication. The untrusted device uses its camera sensor to capture visual authentication codes displayed on a trusted device, or its microphone sensor to capture sound-based authentication keys. This substitution maintains security by using unique authentication credentials while dramatically improving ease of operation, as users simply need to display or speak the authentication key rather than manually input complex credentials on an unfamiliar device.
Solution Approach 2:
The authentication key is created as a copy of the user's identity credentials that can be transferred through multiple media formats (visual display, sound output). This copied authentication information can be presented to the untrusted device through simple actions like displaying a screen or playing a sound, eliminating the need for complex manual input while maintaining the security properties of the original authentication mechanism.
4Adaptability or versatility
If access is granted to untrusted devices, then adaptability is improved, but security deteriorates
Solution Approach 1:
The authentication key acts as an intermediary security layer that enables adaptability to untrusted devices without compromising security. The device receives and verifies the authentication key, which serves as a mediator between the user's trusted credentials and the untrusted device environment. This allows the system to adapt to various untrusted devices (public computers, borrowed phones, smart TVs) while maintaining security through the authentication key verification process.
Solution Approach 2:
The patent implements local quality by providing different authentication experiences tailored to each device type. The authentication key can be presented in formats suitable for the specific device capabilities (visual code for devices with screens, sound for devices with audio output). This localized approach allows secure access to diverse untrusted devices while adapting to their specific characteristics, improving adaptability without sacrificing security.
Data Source
AI summary
A method, system, and manufacture for authorizing an untrusted client device for access on a content management system. The content management system receives a request from an untrusted client device to access content on the content management system. The content management system sends an authentication key to the untrusted client device. The content management system then receives the authentication key from a trusted client device. Based on the matching authentication key, the content management system transmits data to the untrusted client device in accordance with any additional instructions that the trusted client device may have sent.


